Exchange Admin Audit Log Event ID 25324
25324: Remove-RetentionPolicyTag Exchange cmdlet issued
This is an event from
Exchange
audit event from
LOGbinder EX
generated by
.
On this page
See also the TechNet article on the cmdlet Remove-RetentionPolicyTag
Free Security Log Resources by Randy
Field |
Description |
Occurred |
Date and time when Exchange registered the cmdlet. |
Cmdlet |
The cmdlet that was issued. |
Performed by |
The user who issued the cmdlet. |
Succeeded |
"Yes", if succeeded, "No", otherwise. |
Error |
"None", if the cmdlet resulted in no error, the error message otherwise. |
Originating server |
The host name of the server. |
Object modified |
The object that was modified by the cmdlet. |
Parameters |
The list of parameters, listing them by the parameter's Name and Value. |
Modified properties |
Modified properties, if any (otherwise "n/a"). |
Additional information |
Additional information, if any (otherwise "n/a"). |
Setup PowerShell Audit Log Forwarding in 4 Minutes
This Event Is Produced By
Which Integrates with Your SIEM
Remove-RetentionPolicyTag Exchange cmdlet issued
Occurred: 7/7/2014 6:24:37 PM
Cmdlet: Remove-RetentionPolicyTag
Performed by: lb.local/Users/Administrator
Succeeded: Yes
Error: n/a
Originating server: DEV1 (15.00.0516.025)
Object modified: 1 month premanent delete audit log search results
Parameters
Name: Identity, Value: [1 month premanent delete audit log search results]
Modified Properties
n/a
Additional information: CmdletParameters/Parameter/Name= [Identity]; CmdletParameters/Parameter/Value= [1 month premanent delete audit log search results]
For more information, see http://www.ultimatewindowssecurity.com/securitylog/encyclopedia/event.aspx?eventid=25324
Top 10 Windows Security Events to Monitor
Free Tool for Windows Event Collection